Skip to main content
jfelix09
Staff
Staff
July 20, 2026

Troubleshooting Tip: FortiGate HA Cluster Fails to Synchronize after firmware upgrade to FortiOS v7.6.7 and v8.0.0

  • July 20, 2026
  • 0 replies
  • 569 views

Description

This article describes the issue of a FortiGate High Availability (HA) cluster failing to synchronize after a firmware upgrade to FortiOS v7.6.7 or v8.0.0.
The user may encounter an out-of-sync error message for 'user.krb-keytab', indicating that the Kerberos keytab is not synchronized across cluster members.

Scope

 FortiGate v7.6.7 and v8.0.0.

Solution

After upgrading to FortiOS 7.6.7 or 8.0.0, the HA cluster may report an out-of-sync status due to a checksum mismatch for 'user.krb-keytab' between the HA members.

This checksum can be verified in FortiGate GUI under FortiGate GUI -> System -> HA by hovering the mouse over the unsynchronized device to see the tables that are out of sync and the checksum values, or in FortiGate CLI by running the following command in both HA members: 

diagnose sys ha checksum show root | grep user.krb-keytab


This issue is caused by an internal change introduced under issue 1158451 that modified how Kerberos keytab data is stored, encrypted, and decrypted.

As a result, the 'ser.krb-keytab' checksum may differ between HA members following the firmware upgrade, even though the configuration itself has not changed.

This issue will be fixed in the upcoming FortiOS releases v7.6.8 and v8.0.1. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!